ClaimCheck · Legal

Privacy Policy

ClaimCheck asks about data breaches, so we keep what we collect deliberately small. This page explains exactly what we hold and why.

Last updated: 29 August 2026

What we collect

  • Questionnaire answers — the services you used, the incidents you believe affected you, approximate years, your state or territory, and any notes you add.
  • Report records — the generated report, its matches, and whether it has been unlocked.
  • Email address — only if you provide one at checkout so we can send your receipt. We also record the delivery status of that email (queued, sent, bounced or failed) so we can show it to you on your report page.
  • Payment metadata — the payment status and reference returned by Stripe.
  • Sign-in details — if you choose to sign in (to connect ClaimCheck to an authorised AI assistant or app), we receive your name, email address and profile picture from Google, Apple or Microsoft, depending on which provider you choose. We do not receive your password for those services.
  • Usage analytics — only if you accept analytics cookies, we collect de-identified product events (for example, that a questionnaire was completed or a report unlocked) via PostHog to understand and improve the service. IP address collection is disabled.

What we deliberately do not collect

  • No account passwords for any third-party service.
  • No government identifiers, licence or passport numbers.
  • No card numbers, CVCs or bank details — these are entered directly with Stripe and never reach our systems.
  • No copies of breach notification letters or documents.

How we use it

Your answers are used to produce your report, to let you re-open that report with your report link, to process your payment, and to email your receipt. We use aggregate, non-identifying counts to understand which actions people search for. We do not sell your information, and we do not pass your details to law firms or claim-management businesses.

Live research queries

When no curated match exists, we may send a short, de-identified search query (for example "Australian class action Ticketek data breach 2024") to our research and AI providers to look for recent proceedings. These queries contain the incident topic only — never your email address, notes, or a combination that identifies you.

Cookies and consent

We store a small number of essential items in your browser (for example, your cookie preference and sign-in session). Analytics cookies load only after you accept them, and you can change your choice at any time on our Cookie Policy page.

Who processes data for us

  • Stripe — payment processing.
  • Our cloud backend — database, authentication and report hosting.
  • Email provider — sending receipts.
  • Google, Apple and Microsoft — sign-in, only if you choose one of those providers.
  • PostHog — product analytics, only if you accept analytics cookies.
  • AI and search providers — de-identified research queries and report synthesis.

Storage, security and retention

Reports are stored in an access-controlled database. Guest reports are reachable only via a long random report link, which acts as the key — treat it like a password. We retain reports for 12 months so you can revisit them, and payment records for as long as tax and accounting law requires.

Your rights

You may ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete your report. Contact us using the address on your receipt email. You can also complain to the Office of the Australian Information Commissioner if you are not satisfied with how we have handled your information.

Related pages